Description
Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1.
Published: 2026-04-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unauthorized Access to Shipping Rate Management
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows users with insufficient permissions to manipulate shipping rates in the ShipTime: Discounted Shipping Rates plugin. Because the plugin fails to enforce proper access control, an attacker could add, modify, or delete discount rules, resulting in financial loss or billing inaccuracies. The weakness aligns with CWE-862, indicating a broken access control that can lead to data tampering and unauthorized privilege escalation.

Affected Systems

Any WordPress installation that has the ShipTime: Discounted Shipping Rates plugin version 1.1.1 or earlier. The plugin is identified under the vendor product shiptime:ShipTime: Discounted Shipping Rates. No specific OS or WordPress core version constraints are noted; the issue lies solely in the plugin code. The affected range includes all builds from the earliest available version up to and including 1.1.1.

Risk and Exploitability

The CVSS score is not supplied, and no EPSS value is available, so the exact numerical severity cannot be stated. However, the flaw is not included in the CISA Known Exploited Vulnerabilities catalog, suggesting no publicly documented exploit at this time. The likely attack vector is through Web interfaces exposed by the plugin; an attacker may access administrative endpoints without proper authentication or adequate privilege, as the access checks are omitted. Because the flaw is a direct authorization bypass, exploitation is straightforward once the plugin is present on a site.

Generated by OpenCVE AI on April 8, 2026 at 09:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ShipTime: Discounted Shipping Rates plugin to the latest version (1.1.2 or later) if available; if a newer release does not exist, consider removing the plugin entirely.
  • If removal is not feasible, disable the discounting feature or restrict access to the plugin’s admin pages through additional role or capability checks.
  • Review the active WordPress user roles and permissions to ensure that only trusted administrators have editing rights to shipping methods.
  • Conduct an audit of shipping rate data for tampering or unexpected changes following a known vulnerability period.
  • Monitor website logs for abnormal access patterns to the plugin’s administrative endpoints and apply web application firewall rules to block suspicious requests.

Generated by OpenCVE AI on April 8, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Shiptime
Shiptime shiptime: Discounted Shipping Rates
Wordpress
Wordpress wordpress
Vendors & Products Shiptime
Shiptime shiptime: Discounted Shipping Rates
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1.
Title WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Shiptime Shiptime: Discounted Shipping Rates
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T19:45:11.284Z

Reserved: 2026-04-07T10:57:59.671Z

Link: CVE-2026-39672

cve-icon Vulnrichment

Updated: 2026-04-08T19:15:41.346Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:38.687

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-39672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:41:03Z

Weaknesses